CVE-2024-31403: Medium severity cybozu garoon vulnerability
Published Jun 11, 2024
·Updated
Incorrect authorization vulnerability in Cybozu Garoon 5.0.0 to 6.0.0 allows a remote authenticated attacker to alter and/or obtain the data of Memo.
Affected Software
2 affected components
Cybozu Garoon>=5.0.0<6.0.0
Cybozu Garoon>=5.5.0<6.0.1
Event History
Jun 11, 2024
CVE Published
via MITRE·04:27 AM
Data Sourced
via MITRE·04:27 AM
DescriptionWeakness
Data Sourced
via NVD·05:15 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2024-31403?
CVE-2024-31403 is classified as a high severity vulnerability due to its potential impact on data integrity and confidentiality.
2
How do I fix CVE-2024-31403?
To mitigate CVE-2024-31403, update Cybozu Garoon to version 6.0.1 or later, which contains the necessary security patches.
3
What versions of Cybozu Garoon are affected by CVE-2024-31403?
CVE-2024-31403 affects Cybozu Garoon versions from 5.0.0 to 6.0.0 inclusive.
4
Can an attacker exploit CVE-2024-31403 remotely?
Yes, a remote authenticated attacker can exploit CVE-2024-31403 to alter or obtain data from Memo.
5
What kind of data can be compromised due to CVE-2024-31403?
CVE-2024-31403 allows unauthorized access to and modification of Memo data within Cybozu Garoon.